Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2020-1343

Published Jun 9, 2020

An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Code Live Share Information Disc…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2013

Published May 13, 2020

A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie.…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4667

Published May 11, 2020

IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attac…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4092

Published May 6, 2020

"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5879

Published Apr 30, 2020

On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a Server SSL profile is applied.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5865

Published Apr 23, 2020

In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11685

Published Apr 22, 2020

In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11557

Published Apr 9, 2020

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19127

Published Mar 25, 2020

An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related to unencrypted communications…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 651-675 of 897 CVEsPage 27 of 36